Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

DraftKings’ AI Model Targets Loss‑Making Gamblers with Promotions

Investigations reveal DraftKings uses a machine‑learning model to identify and push promotions to customers who are losing money, raising concerns about responsible AI use and consumer protection. Organizations should assess AI‑risk controls to demonstrate trustworthy, compliant practices.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

DraftKings’ AI Model Targets Loss‑Making Gamblers with Promotions

What Happened — Investigations by The New York Times and ProPublica reveal that DraftKings’ machine‑learning model scores customers on how likely they are to increase betting after receiving a promotion. The model uses betting frequency, loss amounts, and account balances to push targeted offers to users who are already losing money.

Why It Matters for Trust & Control Assurance

  • This scenario tests the control objective of responsible AI governance – ensuring that automated decision‑making systems are designed, deployed, and monitored to avoid harmful outcomes.
  • Continuous control‑assurance programs need documented policies, impact assessments, and monitoring evidence to demonstrate that AI models do not exploit vulnerable users.
  • Mapping this to Verisq’s Control Mapping capability helps organizations prove alignment with AI‑risk frameworks (e.g., NIST AI RMF) across multiple compliance regimes.

Who Is Affected – Online gambling platforms, digital‑media advertisers, and any organization that uses AI‑driven personalization for high‑risk consumer segments.

Recommended Actions

  • Conduct an AI‑risk impact assessment focused on consumer‑harm outcomes.
  • Document model design decisions, data sources, and mitigation controls in a continuous‑evidence repository.
  • Implement a monitoring process that flags “elasticity” scores exceeding predefined risk thresholds and triggers responsible‑use reviews.

Source: Malwarebytes Labs

Technical Notes

  • The model ingests transactional betting data (frequency, loss amount, balance) to compute an “elasticity” score.
  • No software vulnerability is disclosed; the risk stems from the model’s objective and deployment without adequate ethical safeguards.

Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/ai/2026/10/losing-gamblers-pushed-to-bet-more-by-draftkings-ai-report-says ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →